agenthink-mesh / docs /protocol_spec.md
agenthinkmesh's picture
Upload project files
cc26f5c verified
|
Raw History Blame Contribute Delete
5.58 kB

AgenThink Mesh β€” Protocol Specification

NAN-RELAY/1.0 Β· NAN-HS/1.0 Β· Grounding Gate/1.0

Status: Draft v0.1
Authors: AgenThink Engineering
Date: March 2026


1. Overview

The National Agentic Network (NAN) Protocol defines how AI agents discover, authenticate, and communicate with each other via the AgenThink Mesh orchestration layer.

It answers three questions every multi-agent system must answer:

  1. Where is the right agent? β†’ Universal Agent Directory (UAD)
  2. What does the next agent need to know? β†’ State-Relay Protocol
  3. Is the agent's output trustworthy? β†’ Grounding Gate

2. NAN Address Scheme

Every agent in the Mesh has a globally unique NAN address:

nan://<country>/<domain>/<name>/<version>

Examples:
  nan://kw/finance/etf-allocator/2.1
  nan://global/research/web-researcher/2.1
  nan://ae/legal/adgm-compliance/1.0

Fields:

  • country β€” ISO 3166-1 alpha-2 country code, or global
  • domain β€” functional category (finance, legal, research, strategy, compliance, meta)
  • name β€” kebab-case agent identifier
  • version β€” semantic version (major.minor)

3. State-Relay Protocol (NAN-RELAY/1.0)

3.1 State-Packet Structure

{
  "packet_id":       "sp_8f3a92c1d",
  "mission_id":      "msn_001",
  "sequence":        2,
  "from_agent":      "nan://global/research/web-researcher/2.1",
  "to_agent":        "nan://kw/legal/contract-analyst/1.5",
  "context": {
    "Research Agent": {
      "output":    "...",
      "timestamp": "2026-03-01T09:14:22Z"
    },
    "_summary": "Rolling mission summary..."
  },
  "partial_output":  "Agent A output here",
  "confidence":      0.91,
  "grounding": {
    "result":            "passed",
    "sources_verified":  ["https://source1.com", "https://source2.com"],
    "confidence_delta":  0.02
  },
  "is_rerouted":     false,
  "expires_at":      "2026-03-01T09:19:22Z",
  "mesh_signature":  "NAN-SIG:sha256:7f2a...b4c9",
  "issued_by":       "nan://mesh/orchestrator/core/1.0"
}

3.2 Relay Flow

Agent A Output
      β”‚
      β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚    Grounding Gate           β”‚  ← verifies claims via MCP web search
β”‚    (hallucination check)    β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
      β”‚ PASS                  β”‚ FAIL β†’ Rerouter evaluates failover
      β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚    State-Packet Factory     β”‚  ← merges A's output into context
β”‚    create_packet(...)       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
      β”‚
      β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚    Orchestrator Router      β”‚  ← selects next agent from pipeline
β”‚    relay_engine.relay(...)  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
      β”‚
      β–Ό
   Agent B receives full State-Packet
   (no context loss, no re-onboarding)

4. Grounding Gate (Grounding-Gate/1.0)

4.1 Trigger Conditions

The Grounding Gate activates on every agent output that contains:

  • Numerical claims (years, percentages, financial figures)
  • Recency signals ("current", "latest", "as of")
  • Attribution phrases ("according to", "reported by")
  • Legal/regulatory references

4.2 Verification Method

Claims are verified via MCP web search (2026 standard):

# MCP tool call
{
  "type": "web_search_20260101",
  "name": "web_search"
}

4.3 Pass/Fail Thresholds

Condition Action
≀ 2 claims fail verification PASS
> 2 claims fail verification FAIL β†’ trigger Rerouter
No verifiable claims found AUTO-PASS
require_grounding=False SKIP

5. Dynamic Rerouting

5.1 Reroute Triggers

Trigger Severity Action
Agent unreachable HIGH Immediate reroute
Grounding Gate FAIL CRITICAL Immediate reroute
Confidence < 0.70 MEDIUM Reroute if alternative available
Latency > 2Γ— SLA LOW Log warning, continue

5.2 Agent Scoring (for reroute selection)

score = (trust_tier_weight Γ— 0.40) +
        (trust_score Γ— 0.30) +
        (domain_match Γ— 0.20) +
        (latency_score Γ— 0.10)

5.3 Trust Score Updates

After every mission step, the Rerouter adjusts the agent's trust score:

  • +0.02 on success
  • +0.01 bonus for meeting latency SLA
  • βˆ’0.05 on failure
  • βˆ’0.03 additional penalty for severe latency breach (> 2Γ— SLA)

6. Authentication (NAN-HS/1.0)

All agent-to-mesh communication uses:

  • mTLS β€” mutual TLS with 15-minute rotating certificates
  • JWT β€” signed with Ed25519, 15-minute expiry
  • Packet Signature β€” SHA-256 HMAC on packet payload

Production environments additionally require:

  • ADGM Digital Asset registry anchoring for T1_SOVEREIGN agents
  • PDPL-compliant data residency enforcement for Kuwait jurisdiction

7. Compatibility

Standard Version Notes
LangGraph β‰₯ 0.2.0 State machine orchestration
PydanticAI β‰₯ 0.0.14 Schema validation
MCP β‰₯ 1.0.0 Web search + tool calls
FastAPI β‰₯ 0.115.0 Orchestrator API
Python β‰₯ 3.11 Type system requirements

AgenThink Β· Kuwait City Β· ADGM-Registered Β· MIT License